{"schema_version":1,"title":"github.com/traefik/traefik (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in github.com/traefik/traefik (Go): 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef…, was published on 22 July 2026.","url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik","json_url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-traefik-traefik","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":18,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":10},"latest":[{"cvss":4,"slug":"duplicate-advisory-traefik-gateway-api-httproute-backendref-5cdb722d","title":"Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-traefik-gateway-api-httproute-backendref-5cdb722d"},{"cvss":5.3,"slug":"traefik-ingressroutetcp-authorization-bypass-in-serverstransport-f9ba5cbc","title":"Traefik IngressRouteTCP authorization bypass in serversTransport references","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-ingressroutetcp-authorization-bypass-in-serverstransport-f9ba5cbc"},{"cvss":5.3,"slug":"traefik-namespace-confusion-in-kubernetes-gateway-api-httproute-36c0eda5","title":"Traefik namespace confusion in Kubernetes Gateway API HTTPRoute","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-namespace-confusion-in-kubernetes-gateway-api-httproute-36c0eda5"},{"cvss":4,"slug":"duplicate-advisory-traefik-crd-ingressroutetcp-serverstransport-cross-e5f042ef","title":"Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-traefik-crd-ingressroutetcp-serverstransport-cross-e5f042ef"},{"cve":"CVE-2026-53622","cvss":3.1,"epss":0.0063,"slug":"cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure","title":"Traefik mTLS bypass in HTTP/3 via exact SNI lookup failure","severity":"high","exploited":false,"published_at":"2026-06-23T20:16:48.777+00:00","url":"https://junglewise.ai/threats/cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure"},{"cvss":7.5,"slug":"traefik-http-2-denial-of-service-via-rapid-stream-reset-74eecc34","title":"Traefik HTTP/2 denial of service via rapid stream reset","severity":"high","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/traefik-http-2-denial-of-service-via-rapid-stream-reset-74eecc34"},{"cvss":3.1,"slug":"duplicate-advisory-traefik-vulnerable-to-http-2-request-causing-denial-f68d45de","title":"Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service","severity":"low","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-traefik-vulnerable-to-http-2-request-causing-denial-f68d45de"},{"cve":"CVE-2026-29777","cvss":4,"epss":0.0038,"slug":"cve-2026-29777-traefik-kubernetes-gateway-rule-injection-via-unescaped-backticks","title":"Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values","severity":"medium","exploited":false,"published_at":"2026-03-11T14:49:44+00:00","url":"https://junglewise.ai/threats/cve-2026-29777-traefik-kubernetes-gateway-rule-injection-via-unescaped-backticks"},{"cvss":3.1,"slug":"traefik-affected-by-tls-clientauth-bypass-on-http-3-5edf78f6","title":"Traefik affected by TLS ClientAuth Bypass on HTTP/3","severity":"low","exploited":false,"published_at":"2026-02-20T21:14:27+00:00","url":"https://junglewise.ai/threats/traefik-affected-by-tls-clientauth-bypass-on-http-3-5edf78f6"},{"cve":"CVE-2025-66490","cvss":4,"epss":0.0037,"slug":"cve-2025-66490-path-normalization-bypass-in-traefik-router-middleware-rules","title":"Path Normalization Bypass in Traefik Router + Middleware Rules","severity":"medium","exploited":false,"published_at":"2025-12-08T16:42:30+00:00","url":"https://junglewise.ai/threats/cve-2025-66490-path-normalization-bypass-in-traefik-router-middleware-rules"},{"cve":"CVE-2024-45410","cvss":3.1,"epss":0.0151,"slug":"cve-2024-45410-http-client-can-manipulate-custom-http-headers-that-are-added-by","title":"HTTP client can manipulate custom HTTP headers that are added by Traefik","severity":"low","exploited":false,"published_at":"2024-09-19T14:48:10+00:00","url":"https://junglewise.ai/threats/cve-2024-45410-http-client-can-manipulate-custom-http-headers-that-are-added-by"},{"slug":"traefik-has-unexpected-behavior-with-ipv4-mapped-ipv6-addresses-74b8e0af","title":"Traefik has unexpected behavior with IPv4-mapped IPv6 addresses","severity":"info","exploited":false,"published_at":"2024-06-11T19:29:43+00:00","url":"https://junglewise.ai/threats/traefik-has-unexpected-behavior-with-ipv4-mapped-ipv6-addresses-74b8e0af"},{"cvss":3.1,"slug":"traefik-vulnerable-to-go-issue-allowing-malformed-dns-message-to-cause-b757b563","title":"Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop","severity":"low","exploited":false,"published_at":"2024-05-23T15:19:41+00:00","url":"https://junglewise.ai/threats/traefik-vulnerable-to-go-issue-allowing-malformed-dns-message-to-cause-b757b563"},{"cve":"CVE-2024-28869","cvss":3.1,"epss":0.0105,"slug":"cve-2024-28869-traefik-vulnerable-to-denial-of-service-with-content-length","title":"Traefik vulnerable to denial of service with Content-length header","severity":"low","exploited":false,"published_at":"2024-04-12T17:05:13+00:00","url":"https://junglewise.ai/threats/cve-2024-28869-traefik-vulnerable-to-denial-of-service-with-content-length"},{"cve":"CVE-2019-12452","cvss":3,"epss":0.0254,"slug":"cve-2019-12452-containous-traefik-exposes-password-hashes","title":"Containous Traefik Exposes Password Hashes","severity":"low","exploited":false,"published_at":"2022-05-24T16:46:50+00:00","url":"https://junglewise.ai/threats/cve-2019-12452-containous-traefik-exposes-password-hashes"},{"cve":"CVE-2018-15598","cvss":3,"epss":0.0287,"slug":"cve-2018-15598-traefik-missing-authentication","title":"Traefik Missing Authentication","severity":"low","exploited":false,"published_at":"2022-05-13T01:07:40+00:00","url":"https://junglewise.ai/threats/cve-2018-15598-traefik-missing-authentication"},{"cve":"CVE-2020-9321","cvss":3.1,"epss":0.0074,"slug":"cve-2020-9321-traefik-has-an-improper-certificate-handling-issue","title":"Traefik has an Improper Certificate Handling issue","severity":"low","exploited":false,"published_at":"2021-09-02T22:00:01+00:00","url":"https://junglewise.ai/threats/cve-2020-9321-traefik-has-an-improper-certificate-handling-issue"},{"cve":"CVE-2021-32813","cvss":3.1,"epss":0.011,"slug":"cve-2021-32813-header-dropping-in-traefik","title":"Header dropping in traefik","severity":"low","exploited":false,"published_at":"2021-08-05T17:04:21+00:00","url":"https://junglewise.ai/threats/cve-2021-32813-header-dropping-in-traefik"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://traefik.io/traefik/","repo_url":"https://github.com/traefik/traefik","description":"An HTTP reverse proxy and load balancer for deploying microservices.","url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},"most_severe":[{"cvss":7.5,"slug":"traefik-http-2-denial-of-service-via-rapid-stream-reset-74eecc34","title":"Traefik HTTP/2 denial of service via rapid stream reset","severity":"high","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/traefik-http-2-denial-of-service-via-rapid-stream-reset-74eecc34"},{"cve":"CVE-2026-53622","cvss":3.1,"epss":0.0063,"slug":"cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure","title":"Traefik mTLS bypass in HTTP/3 via exact SNI lookup failure","severity":"high","exploited":false,"published_at":"2026-06-23T20:16:48.777+00:00","url":"https://junglewise.ai/threats/cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure"},{"cvss":5.3,"slug":"traefik-ingressroutetcp-authorization-bypass-in-serverstransport-f9ba5cbc","title":"Traefik IngressRouteTCP authorization bypass in serversTransport references","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-ingressroutetcp-authorization-bypass-in-serverstransport-f9ba5cbc"},{"cvss":5.3,"slug":"traefik-namespace-confusion-in-kubernetes-gateway-api-httproute-36c0eda5","title":"Traefik namespace confusion in Kubernetes Gateway API HTTPRoute","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-namespace-confusion-in-kubernetes-gateway-api-httproute-36c0eda5"},{"cve":"CVE-2026-29777","cvss":4,"epss":0.0038,"slug":"cve-2026-29777-traefik-kubernetes-gateway-rule-injection-via-unescaped-backticks","title":"Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values","severity":"medium","exploited":false,"published_at":"2026-03-11T14:49:44+00:00","url":"https://junglewise.ai/threats/cve-2026-29777-traefik-kubernetes-gateway-rule-injection-via-unescaped-backticks"},{"cve":"CVE-2025-66490","cvss":4,"epss":0.0037,"slug":"cve-2025-66490-path-normalization-bypass-in-traefik-router-middleware-rules","title":"Path Normalization Bypass in Traefik Router + Middleware Rules","severity":"medium","exploited":false,"published_at":"2025-12-08T16:42:30+00:00","url":"https://junglewise.ai/threats/cve-2025-66490-path-normalization-bypass-in-traefik-router-middleware-rules"},{"cvss":4,"slug":"duplicate-advisory-traefik-gateway-api-httproute-backendref-5cdb722d","title":"Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-traefik-gateway-api-httproute-backendref-5cdb722d"},{"cvss":4,"slug":"duplicate-advisory-traefik-crd-ingressroutetcp-serverstransport-cross-e5f042ef","title":"Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass","severity":"medium","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-traefik-crd-ingressroutetcp-serverstransport-cross-e5f042ef"},{"cve":"CVE-2024-45410","cvss":3.1,"epss":0.0151,"slug":"cve-2024-45410-http-client-can-manipulate-custom-http-headers-that-are-added-by","title":"HTTP client can manipulate custom HTTP headers that are added by Traefik","severity":"low","exploited":false,"published_at":"2024-09-19T14:48:10+00:00","url":"https://junglewise.ai/threats/cve-2024-45410-http-client-can-manipulate-custom-http-headers-that-are-added-by"},{"cve":"CVE-2021-32813","cvss":3.1,"epss":0.011,"slug":"cve-2021-32813-header-dropping-in-traefik","title":"Header dropping in traefik","severity":"low","exploited":false,"published_at":"2021-08-05T17:04:21+00:00","url":"https://junglewise.ai/threats/cve-2021-32813-header-dropping-in-traefik"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}